Skip to main content
Templates & Checklists

IT Company Compliance: Annual Checklist for Tech Subsidiaries in India

A practical annual compliance checklist covering every obligation that IT and technology subsidiaries in India must fulfill, from ROC filings and transfer pricing to DPDP Act data protection and CERT-In cybersecurity requirements.

March 20, 20268 min read
8 min readLast updated September 4, 2026
Written by Shreya Pandey, Associate, Corporate ComplianceReviewed by Priyanka Khurana, Company Secretary

Why IT Subsidiaries Face a Heavier Compliance Burden

Beyond the baseline Companies Act 2013, the Income-tax Act, 2025 (which replaced the Income-tax Act, 1961 for tax years beginning on or after 1 April 2026), and GST obligations every Indian company carries, IT subsidiaries — especially those owned by foreign parents — must also navigate FEMA reporting for cross-border capital flows, transfer pricing documentation, Digital Personal Data Protection Act 2023 obligations, CERT-In cybersecurity incident reporting, and sector-specific STPI or SEZ rules. Missing a deadline in any of these areas carries real cost: penalties range from INR 5,000 for a late DIR-3 KYC filing to INR 250 crore under the DPDP Act for serious data protection violations.

For foreign-owned tech subsidiaries, non-compliance also creates complications for future investment rounds, exits, and repatriation of profits. Use this checklist, organized by compliance category, as a monthly and quarterly tracker to ensure nothing falls through the cracks.

Corporate Governance and ROC Filings

These obligations apply to every Private Limited Company in India, regardless of sector.

Board Meetings

A minimum of four board meetings must be held per year, with no more than 120 days between consecutive meetings. For IT subsidiaries with foreign directors, note that directors can participate via video conferencing for most agenda items, but approval of the annual financial statements and the Board's report is on the Rule 4 list of matters that cannot be dealt with in a video-conference meeting — the proviso to Rule 4 requires a quorum of directors physically present, after which other directors may join by video conferencing.

  • Quorum: One-third of total board strength or two directors, whichever is higher
  • Notice: Minimum seven days to all directors
  • Minutes: Must be prepared, signed and entered in the Minutes Book within 30 days of the conclusion of the meeting (Section 118(1)). For a video-conference meeting, Rule 25 additionally requires draft minutes to be circulated within 15 days

Annual General Meeting (AGM)

Must be held within six months from the end of the financial year. For companies with a March 31 year-end, the AGM deadline is September 30. The agenda must include adoption of audited financial statements, appointment or reappointment of auditors, and appointment of directors retiring by rotation.

Key ROC Filings

FormPurposeDeadlinePenalty for Late Filing
AOC-4Filing of audited financial statementsWithin 30 days of AGMAdditional fee of INR 100 per day (no cap) under Section 403, plus the Section 137(3) penalty: INR 10,000 on the company plus INR 100 per day, capped at INR 2 lakh
MGT-7 / MGT-7AAnnual return with shareholder and director detailsWithin 60 days of AGMAdditional fee of INR 100 per day (no cap) under Section 403, plus the Section 92(5) penalty: INR 10,000 plus INR 100 per day, capped at INR 2 lakh for the company and INR 50,000 for each officer
DIR-3 KYCDirector KYC verification (once every three financial years)30 June (not annual since G.S.R. 943(E), eff. 31 Mar 2026; superseded the 30 September date)INR 5,000 flat + DIN deactivation
ADT-1Auditor appointment intimationWithin 15 days of AGMAdditional fee under Section 403 on a slab basis, rising with the length of delay to a multiple of the normal filing fee
DPT-3Return of deposits and outstanding loansJune 30Rule 21 of the Deposit Rules: fine up to INR 5,000, and up to INR 500 per day for a continuing default
MSME-1Outstanding dues to MSME vendorsHalf-yearly (April 30, October 31)Section 405(4): INR 20,000 plus INR 1,000 per day of continuing default, capped at INR 3 lakh

IT subsidiaries that engage MSME vendors for software testing, content creation, or staff augmentation must pay particular attention to MSME-1 filing. Delayed payments to MSME suppliers beyond 45 days attract compound interest at three times the bank rate.

Article illustration

Income Tax Compliance

Advance Tax Instalments

Companies must pay advance tax in four quarterly instalments:

  • June 15: 15% of estimated tax liability
  • September 15: 45% cumulative
  • December 15: 75% cumulative
  • March 15: 100% of estimated tax liability

Shortfall in advance tax attracts interest under sections 424 and 425 of the Income-tax Act, 2025 (sections 234B and 234C of the Income-tax Act, 1961). The standard corporate tax rate for IT companies opting for section 200 read with section 205(1) of the Income-tax Act, 2025 (section 115BAA of the Income-tax Act, 1961) is 22%, an effective 25.17% after the 10% surcharge and 4% cess. Outside that regime, the First Schedule Part III to the Finance Act, 2026 charges a domestic company 25% where its total turnover or gross receipts in tax year 2024-25 did not exceed INR 400 crore, and 30% otherwise; the surcharge is 7% where total income exceeds INR 1 crore and 12% where it exceeds INR 10 crore, so the top effective rate is 34.94%. A foreign company is charged at 35% plus a 2% or 5% surcharge.

Income Tax Return Filing

Every company must file a return of income regardless of turnover or profit. For a company the due date is 31 October of the assessment year; a company with international transactions requiring an accountant's report under Section 172 of the Income-tax Act, 2025 (Section 92E of the Income-tax Act, 1961) has until 30 November. The INR 1 crore / INR 10 crore figures are the tax-audit thresholds below, not filing thresholds.

Tax Audit (Section 63 of the Income-tax Act, 2025; Section 44AB of the Income-tax Act, 1961)

Required where turnover exceeds INR 1 crore, or INR 10 crore where cash receipts and cash payments each stay within 5% of the total. The audit report is due one month before the return due date — 30 September of the assessment year.

Transfer Pricing: The Critical IT Subsidiary Obligation

This is where most foreign-owned IT subsidiaries face the highest risk. Every intercompany transaction, whether it involves software development services, IP licensing, management fees, or cost-sharing arrangements, must be priced at arm's length and documented thoroughly.

Key Filing Requirements

  • Form 48 (formerly Form 3CEB): Transfer pricing audit report, due by October 31 of the assessment year — one month before the November 30 income tax return due date for companies with transfer pricing obligations
  • Form No. 49: the safe-harbour option form under the Income-tax Rules, 2026, replacing Form 3CEFA. For IT services it is filed with the Director General of Income-tax (Systems), not the Assessing Officer
  • Local File: Transaction-level documentation with comparability analysis
  • Master File: Required only when both conditions are met — the international group's consolidated revenue exceeds INR 500 crore and the aggregate value of international transactions exceeds INR 50 crore (or INR 10 crore for transactions in intangible property). The two limbs are cumulative, not alternative (Rule 10DA(1))
  • Country-by-Country Report (CbCR): Required where the international group's total consolidated revenue exceeds INR 6,400 crore (Rule 10DB(6)). The reporting obligation itself is now in Section 511 of the Income-tax Act, 2025 (Section 286 of the Income-tax Act, 1961)

Safe Harbour for IT Services

The framework was rewritten from the ground up. For tax year 2026-27 onwards, rule 89(2) of the Income-tax Rules, 2026 sets a single safe-harbour margin of 15.5% of operating expense for the provision of information technology services — software development, ITeS, knowledge process outsourcing and software-related contract R&D all folded into one category — where aggregate operating revenue from the transaction does not exceed INR 2,000 crore. Rule 89(4) fixes the rate table for a block of three tax years beginning with 2026-27.

The election runs on a different clock. Under rule 91(1), once validly exercised for IT services the option stays in force for five consecutive tax years, with the INR 2,000 crore threshold tested only in the first of them (rule 91(2)). It is made in Form No. 49 with the Director General of Income-tax (Systems), by the return due date under Section 263(1)(c), and cannot be withdrawn after six months from the end of the first tax year (rule 91(10)). Do not describe the rates as a five-year block or the election as a three-year one — they are separate periods that happen to start in the same year.

Two other rows matter to technology groups: data centre services is a new category at a 15% margin, and corporate guarantees keep the 1% rate with the INR 100 crore / credit-rating condition now sitting in the eligibility rule (rule 88(c)).

For FY 2025-26 and earlier tax years the old framework still governs, because Section 536(2)(c) of the Income-tax Act, 2025 keeps the 1961 Act in force for those years. Under Rule 10TD of the Income-tax Rules, 1962 as amended by Notification 21/2025: software development and ITeS margins of not less than 17% where the transaction value did not exceed INR 100 crore and 18% between INR 100 crore and INR 300 crore; KPO at 24% / 21% / 18% tiered by the ratio of employee cost to operating expense. Those figures are history for tax year 2026-27 and must not be quoted as current.

The statutory hook is Section 167 of the Income-tax Act, 2025 (Section 92CB of the Income-tax Act, 1961). Electing safe harbour does not displace the transfer pricing documentation and accountant's-report obligations in Sections 171 and 172 (rule 89(6)), and a price accepted under safe harbour cannot afterwards be taken to mutual agreement procedure under a treaty (rule 93).

Article illustration

FEMA Compliance for Foreign-Owned Subsidiaries

IT subsidiaries with foreign direct investment have mandatory FEMA reporting obligations:

  • FC-GPR: Report any issuance of shares to foreign investors within 30 days of allotment via the RBI's FIRMS portal
  • FLA Return: Annual Return on Foreign Liabilities and Assets, due by July 15 every year, covering the company's foreign assets and liabilities as on March 31
  • Annual Performance Report (APR): Required if the Indian subsidiary has made outward investments. Due by December 31
  • ECB Returns: ECB-2 is a monthly return — due within seven calendar days from the end of any month in which loan drawdown or debt servicing occurs, filed through the designated AD Category-I bank to RBI, if the company has raised external commercial borrowings

For IT subsidiaries, common FEMA triggers include receiving share capital from the parent company, paying royalties or license fees for technology, and making intercompany loan arrangements. Each of these requires specific RBI reporting.

GST Compliance for IT Companies

IT services attract GST at 18%. However, export of software services is classified as a zero-rated supply under GST, meaning no tax is levied on exports if proper documentation is maintained.

Monthly and Quarterly Returns

ReturnFrequencyDeadline
GSTR-1Monthly (or quarterly under QRMP)11th or 13th of following month
GSTR-3BMonthly (or quarterly under QRMP)20th of following month
GSTR-9Annual returnDecember 31 of following financial year
GSTR-9CReconciliation statement (turnover over INR 5 crore)Filed with GSTR-9

Key IT-Specific GST Issues

  • Intermediary services: Section 13(8)(b) of the IGST Act fixed the place of supply of intermediary services at the supplier's location, so an Indian company acting as an intermediary for an overseas principal was taxed as if it were making a domestic supply and was denied export treatment. Section 157 of the Finance Act, 2026 omits that clause, opening zero-rating to those suppliers
  • Reverse Charge on Imported Services: IT subsidiaries importing cloud services (AWS, Azure, GCP), SaaS subscriptions, or technical consulting from the parent must pay GST under reverse charge mechanism
  • Input Tax Credit (ITC): Companies exporting services can claim ITC refunds. Maintain proper documentation and file refund applications within two years of the relevant date
Article illustration

Data Protection: DPDP Act 2023 Compliance

The Digital Personal Data Protection Rules 2025, notified on November 13, 2025, operationalize India's first comprehensive data protection law. IT subsidiaries, especially those processing customer data, employee data, or data of Indian users, must prepare for phased compliance.

Implementation Timeline

  • Immediate (November 2025): Data Protection Board constitution and procedural rules
  • 12 months (November 2026): Consent Manager registration process goes live
  • 18 months (May 2027): Full compliance obligations including privacy notices, security protocols, breach notification within 72 hours, and Significant Data Fiduciary (SDF) obligations

What IT Subsidiaries Must Do Now

  • Conduct a data mapping exercise to identify all personal data processing activities
  • Review and update privacy notices to meet the clear, plain language requirement
  • Implement consent management systems for express, informed consent
  • Update data processor contracts so that the security-safeguard obligations the Act and the DPDP Rules place on a data fiduciary are passed through to the processor by contract
  • Establish breach notification protocols for the 72-hour reporting window
  • Appoint a Data Protection Officer if likely to be classified as a Significant Data Fiduciary

Penalties under the DPDP Act can reach up to INR 250 crore for serious violations, making this a board-level priority.

Cybersecurity: CERT-In Compliance

CERT-In's Directions of 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000 impose mandatory obligations on service providers, intermediaries, data centres, body corporates and government organisations operating in India.

Core Requirements

  • Incident Reporting: All cybersecurity incidents must be reported to CERT-In within 6 hours of detection. This includes unauthorized access, malware, ransomware, DDoS attacks, data breaches, identity theft, and supply chain compromises
  • Log Retention: Security logs must be stored in India for a minimum of 180 days, covering firewall, IDS/IPS, WAF, EDR, identity providers, application access, database activity, VPN gateways, and cloud logs
  • Point of Contact: Designate a specific individual as the cybersecurity point of contact for CERT-In communications
  • KYC of Clients: Data centres and cloud service providers must maintain KYC records of their clients
  • Audits: CERT-In empanels auditors and publishes cyber security audit guidelines covering IT, OT, cloud, supply chain and physical security; sectoral regulators (RBI, SEBI, IRDAI) impose their own audit frequencies on regulated entities. Confirm which cadence binds you rather than assuming a single annual requirement
Article illustration

Labor Law Compliance for IT Companies

The four Labour Codes — the Code on Wages, 2019, the Industrial Relations Code, 2020, the Code on Social Security, 2020 and the Occupational Safety, Health and Working Conditions Code, 2020 — were brought into force with effect from 21 November 2025, rationalising 29 central labour laws. State rules under the Codes are still being framed in several states, so state-level registrations and returns continue to run under the older state rules until each state notifies its own. Confirm the position in every state you employ in.

Key Monthly Obligations

  • PF Contribution: 12% employer + 12% employee, deposited by the 15th of the following month via the EPFO portal
  • ESI Contribution: Applicable if employee wages are below INR 21,000 per month. Employer contributes 3.25%, employee 0.75%
  • TDS on Salaries: Deduct and deposit by the 7th of the following month
  • Professional Tax: State-specific. Karnataka, Maharashtra, and Telangana (major IT hubs) all levy professional tax with different slabs and deadlines

IT-Specific Exemptions

IT companies in several states benefit from exemptions under the Shops and Commercial Establishments Act. Karnataka, for example, has issued successive notifications exempting IT/ITES establishments from the standing-orders regime — formerly the Industrial Employment (Standing Orders) Act, 1946, now subsumed into the Industrial Relations Code, 2020 — for fixed periods. Check the validity window of the notification in force before relying on it. All IT companies must still comply with the core provisions of the state Shops and Establishments Act on working hours, leave and conditions of employment.

Annual Labor Filings

  • Form 130 (formerly Form 16): TDS certificates to employees, by June 15
  • Bonus Payment: Within eight months of the close of the accounting year for eligible employees
  • Gratuity: Payable within 30 days of it becoming due

STPI and SEZ Compliance

IT companies registered under the Software Technology Parks of India (STPI) scheme or operating from a Special Economic Zone (SEZ) have additional compliance requirements.

STPI-Registered Units

  • Monthly Progress Reports: Submit by the 7th of every month
  • Quarterly Reports: Performance and export data
  • SOFTEX Forms: Certification required for all software exports
  • Bond and Bank Guarantee: Maintain as per STPI requirements
  • Annual Performance: Export obligations must be met to retain STPI status

SEZ Units

  • Annual Performance Report: Submit to the Development Commissioner
  • Quarterly Returns: In prescribed formats
  • Net Foreign Exchange Earnings: Must be positive over five years
Article illustration

Intellectual Property Compliance

IT subsidiaries must protect and document their intellectual property arrangements with the parent company.

  • Trademark Registration: File and renew trademarks through the IP India portal. Renewal is due every 10 years
  • Technology License Agreements: Any agreement for use of parent company technology must comply with FEMA pricing guidelines and may require RBI reporting
  • Copyright Registration: While automatic under Indian law, formal registration provides stronger enforcement options
  • Patent Compliance: Keep renewal fees current and file the statement of working (Form 27) for every granted patent within the period the Patents Rules prescribe

Month-by-Month Compliance Calendar

MonthKey Deadlines
AprilAnnual PF return (30th), Board meeting Q1, MSME-1 for H2 (30th)
MayTDS return Q4 (31st), TDS payment for March (30 April)
JuneAdvance tax Q1 (15th), Form 130 to employees (15th), DPT-3 (30th), IEC renewal (DGFT portal)
JulyFLA Return to RBI (15th), Board meeting Q2, TDS return Q1 (31st)
AugustBonus payment deadline
SeptemberAGM deadline (30th), Advance tax Q2 (15th), Tax audit report (30th); DIR-3 KYC — no longer due here annually, now filed once every three financial years by 30 June (G.S.R. 943(E), eff. 31 Mar 2026)
OctoberAOC-4 filing (within 30 days of AGM), ITR-6 filing (31st), Form 48 (31st), TDS return Q2 (31st), MSME-1 for H1 (31st)
NovemberMGT-7 filing (within 60 days of AGM), TP report (30th for companies with international transactions)
DecemberAdvance tax Q3 (15th), APR for outward investments (31st), GSTR-9 annual return (31st)
JanuaryTDS return Q3 (31st)
FebruaryBoard meeting Q3
MarchAdvance tax Q4 (15th), Financial year-end preparation

Statutory Audit and Internal Controls

Every IT subsidiary must appoint a statutory auditor at its first AGM. The auditor holds office for a term of five years (from the conclusion of one AGM to the conclusion of the sixth AGM). Section 143(3)(i) requires the auditor's report to state whether the company has adequate internal financial controls with reference to financial statements and their operating effectiveness. The MCA exemption notification of 13 June 2017 lifts that requirement only for a private company that is a one-person or small company, or whose turnover is below INR 50 crore, or whose aggregate borrowings from banks, financial institutions or body corporates are below INR 25 crore. IT subsidiaries that are part of large multinational groups often fall into this category given the scale of intercompany transactions.

In addition to the statutory audit, IT companies should consider implementing an internal audit function to review compliance processes, particularly around FEMA compliance, transfer pricing documentation, and data protection protocols. An internal audit can identify gaps before they become regulatory issues during external audits or government inspections.

Key Takeaways

  • IT subsidiaries face compliance across at least eight regulatory domains: MCA, income tax, GST, FEMA, transfer pricing, data protection, cybersecurity, and labor law
  • Transfer pricing documentation and the safe harbour election are the single highest-risk compliance area for foreign-owned IT subsidiaries. From tax year 2026-27 the IT-services safe harbour is a single 15.5% margin up to INR 2,000 crore of operating revenue (rule 89(2) of the Income-tax Rules, 2026), elected for five years in Form No. 49
  • The DPDP Act timeline gives IT companies until May 2027 for full compliance, but data mapping, consent frameworks, and breach protocols should be implemented now
  • CERT-In's 6-hour incident reporting requirement applies to all cybersecurity events. Establish a documented incident response plan with clear escalation paths
  • Engage a compliance management firm or appoint an internal compliance officer to maintain a rolling calendar. The cost of proactive compliance management is a fraction of the penalties for missing deadlines

Need help with Templates & Checklists? Our team handles it.

Company Registration Checklist for India
FAQ

Frequently Asked Questions

What is the corporate tax rate for IT companies in India?

IT companies opting for section 200 read with section 205(1) of the Income-tax Act, 2025 (section 115BAA of the Income-tax Act, 1961) pay an effective rate of 25.17% (22% base plus surcharge and cess). Companies not opting for this concessional rate pay the standard rate of 30% plus applicable surcharge and cess. Note that section 201 (Table, Sl. No. 1) read with section 205(2) of the Income-tax Act, 2025 (section 115BAB of the Income-tax Act, 1961) (15% rate) applies only to new manufacturing companies and is not available to IT service companies.

Do IT companies in India need to comply with the DPDP Act?

Yes. The Digital Personal Data Protection Act 2023, operationalized through the DPDP Rules 2025, applies to all companies processing digital personal data in India. Full compliance obligations, including privacy notices, breach notification within 72 hours, and consent management, take effect by May 2027. IT companies should begin preparations immediately given the complexity of implementation.

What are the CERT-In incident reporting requirements for IT companies?

All cybersecurity incidents must be reported to CERT-In within 6 hours of detection. Reportable incidents include unauthorized access, malware, ransomware, DDoS attacks, data breaches, identity theft, and supply chain compromises. Companies must also retain security logs in India for a minimum of 180 days and undergo annual third-party cybersecurity audits.

What transfer pricing safe harbour rates apply to IT subsidiaries?

For tax year 2026-27 onwards, rule 89(2) of the Income-tax Rules, 2026 sets one margin for the provision of information technology services — software development, ITeS, KPO and software-related contract R&D together — of not less than 15.5% of operating expense, where aggregate operating revenue from the transaction does not exceed INR 2,000 crore. The option is exercised in Form No. 49 with the Director General of Income-tax (Systems) and, once valid, runs for five consecutive tax years. The older 17% / 18% software and ITeS margins and the 24% / 21% / 18% KPO ladder (Rule 10TD of the Income-tax Rules, 1962 as amended by Notification 21/2025) apply only to FY 2025-26 and earlier tax years.

Is GST applicable on software exports from India?

No. Export of software services is classified as a zero-rated supply under GST. Section 157 of the Finance Act, 2026 also omits Section 13(8)(b) of the IGST Act, which had placed the supply of intermediary services at the supplier's location and so denied export treatment to Indian companies acting as intermediaries for overseas principals.

What are the penalties for late ROC filings?

Late filing of AOC-4 or MGT-7 attracts an additional fee of INR 100 per day of delay with no upper cap under Section 403 — roughly INR 18,000 per form for a filing six months late — and, separately, a statutory penalty under Section 137(3) or Section 92(5) of INR 10,000 plus INR 100 per day, capped at INR 2 lakh for the company. Directors of companies that fail to file for three consecutive years are disqualified from directorship in any company for five years.

Do STPI-registered IT companies have additional compliance obligations?

Yes. STPI-registered units must submit monthly progress reports by the 7th of each month, quarterly performance reports, certified SOFTEX forms for all software exports, and maintain bonds and bank guarantees. Non-compliance can lead to cancellation of STPI registration and loss of associated benefits.

This article is for general information only and is not legal, tax, or investment advice. Confirm current rules with the relevant authority or a qualified professional — or ask our team. See our full disclaimer.

Topics
IT complianceannual compliance checklisttech subsidiary Indiatransfer pricingDPDP ActCERT-In

Put this guide to work

Our Chartered Accountants and Company Secretaries handle registrations and filings for founders in 80+ countries.

Chat NowBook My Free Consultation